Man-in-the-middle attack in PostgreSQL Java Database Connectivity - CVE-2018-10936
Published: August 31, 2018 / Updated: September 3, 2018
Vulnerability details
The vulnerability allows a remote attacker to conduct man-in-the-middle attacks on the target system.
The vulnerability exists in the PostgreSQL Java Database Connectivity (JDBC) driver due to insufficient validation of hostnames by the affected software. A remote unauthenticated attacker can masquerade as a trusted server on the network, conduct a man-in-the-middle attack and conduct further attacks.
Affected software
Fedora
watsonx.data
postgresql-jdbc
How to mitigate CVE-2018-10936
watsonx.data - update to 2.0.2
postgresql-jdbc - addressed in versions 42.2.5-2.fc28, 42.2.5-2.fc29